File name:

Nero-Burning-ROM-2024-2.0.1.39.exe

Full analysis: https://app.any.run/tasks/a4a227db-f396-4b99-bf79-69f65d8ba675
Verdict: Malicious activity
Analysis date: March 21, 2025, 13:16:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

21A3C33C0C8E1523F11B96C600726A61

SHA1:

EB1C37DF8DEBBAB64975292DE5087C212AEA5A1C

SHA256:

561AD0BC4B7EFF266B53DF72A4887D7F9014EE283DAA63EB491454B6B50348FF

SSDEEP:

98304:Hzx8SlEpoEEvmEBBnR16cGMRP/HLts37lWly7z/tQNrfli2vV9Mh8MRo2w+uUG1M:7peWG9eT2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • NeroInstaller.exe (PID: 7720)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NeroInstaller.exe (PID: 7720)
      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
    • Reads Internet Explorer settings

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • Reads security settings of Internet Explorer

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • Creates a software uninstall entry

      • NeroInstaller.exe (PID: 7720)
    • Searches for installed software

      • NeroInstaller.exe (PID: 7720)
    • Process drops legitimate windows executable

      • NeroInstaller.exe (PID: 7720)
    • The process drops C-runtime libraries

      • NeroInstaller.exe (PID: 7720)
  • INFO

    • Reads the computer name

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • Creates files in the program directory

      • NeroInstaller.exe (PID: 7720)
      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
    • Reads the software policy settings

      • NeroInstaller.exe (PID: 7720)
      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
    • Checks supported languages

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • The sample compiled with english language support

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • Checks proxy server information

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • Create files in a temporary directory

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • Reads the machine GUID from the registry

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
      • NeroInstaller.exe (PID: 7720)
    • Local mutex for internet shortcut management

      • NeroInstaller.exe (PID: 7720)
    • Creates files or folders in the user directory

      • Nero-Burning-ROM-2024-2.0.1.39.exe (PID: 7200)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (78.5)
.exe | Win32 Executable (generic) (11.3)
.exe | Generic Win/DOS Executable (5)
.exe | DOS Executable Generic (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:16 10:27:36+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1434624
InitializedDataSize: 6969344
UninitializedDataSize: -
EntryPoint: 0x10e19f
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.1.39
ProductVersionNumber: 2.0.1.39
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Nero AG
FileDescription: NeroInstaller
FileVersion: 2.0.1.39
InternalName: NeroInstaller
LegalCopyright: Copyright (c) 2003-2024 Nero AG and its licensors
OriginalFileName: burningrom2024
ProductName: NeroInstaller
ProductVersion: 2.0.1.39
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
9
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start nero-burning-rom-2024-2.0.1.39.exe sppextcomobj.exe no specs slui.exe neroinstaller.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs nero-burning-rom-2024-2.0.1.39.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1056"C:\Windows\System32\regsvr32.exe" /s "C:\Program Files (x86)\Nero\Nero Common\Nero Launcher\NeroShellExt.dll"C:\Windows\SysWOW64\regsvr32.exeNeroInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5892 /s "C:\Program Files (x86)\Nero\Nero Common\Nero Launcher\x64\NeroShellExt.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6240"C:\Windows\System32\regsvr32.exe" /s "C:\Program Files (x86)\Nero\Nero Common\Nero Launcher\x64\NeroShellExt.dll"C:\Windows\SysWOW64\regsvr32.exeNeroInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6964"C:\Users\admin\AppData\Local\Temp\Nero-Burning-ROM-2024-2.0.1.39.exe" C:\Users\admin\AppData\Local\Temp\Nero-Burning-ROM-2024-2.0.1.39.exeexplorer.exe
User:
admin
Company:
Nero AG
Integrity Level:
MEDIUM
Description:
NeroInstaller
Exit code:
3221226540
Version:
2.0.1.39
Modules
Images
c:\users\admin\appdata\local\temp\nero-burning-rom-2024-2.0.1.39.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7200"C:\Users\admin\AppData\Local\Temp\Nero-Burning-ROM-2024-2.0.1.39.exe" C:\Users\admin\AppData\Local\Temp\Nero-Burning-ROM-2024-2.0.1.39.exe
explorer.exe
User:
admin
Company:
Nero AG
Integrity Level:
HIGH
Description:
NeroInstaller
Exit code:
4294967295
Version:
2.0.1.39
Modules
Images
c:\users\admin\appdata\local\temp\nero-burning-rom-2024-2.0.1.39.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7260C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7300"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7720"C:\Users\admin\AppData\Local\Temp\Nero-Burning-ROM-2024-2.0.1.39.exe" /noselfupdate /installid burningrom2024 /nomutexcheckC:\Users\admin\AppData\Local\Temp\NeroInstaller\burningrom2024\temp\NeroInstaller\NeroInstaller.exe
Nero-Burning-ROM-2024-2.0.1.39.exe
User:
admin
Company:
Nero AG
Integrity Level:
HIGH
Description:
NeroInstaller
Version:
3.0.1.2
Modules
Images
c:\users\admin\appdata\local\temp\neroinstaller\burningrom2024\temp\neroinstaller\neroinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
8064"C:\Windows\System32\regsvr32.exe" /s "C:\Program Files (x86)\Nero\Nero Common\AdvrCntr6\AdvrCntr6.dll"C:\Windows\SysWOW64\regsvr32.exeNeroInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
2 769
Read events
2 593
Write events
110
Delete events
66

Modification events

(PID) Process:(7200) Nero-Burning-ROM-2024-2.0.1.39.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7200) Nero-Burning-ROM-2024-2.0.1.39.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7200) Nero-Burning-ROM-2024-2.0.1.39.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7720) NeroInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Nero\Nero Launcher
Operation:writeName:installPath
Value:
C:\Program Files (x86)\Nero
(PID) Process:(7720) NeroInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Nero\Nero 10\Shared
Operation:writeName:SendUsageStatistics
Value:
1
(PID) Process:(7720) NeroInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7720) NeroInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7720) NeroInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7720) NeroInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Installer\neropack\226
Operation:writeName:C:\Program Files (x86)\Nero\Nero Common\Nero KnowHow PLUS\NeroKnowHowPLUS.exe
Value:
2025-03-21 13:17:14
(PID) Process:(7720) NeroInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL
Operation:writeName:NeroKnowHowPLUS.exe
Value:
1
Executable files
29
Suspicious files
80
Text files
26
Unknown types
1

Dropped files

PID
Process
Filename
Type
7200Nero-Burning-ROM-2024-2.0.1.39.exeC:\Users\admin\AppData\Local\Temp\NeroInstaller\burningrom2024\NeroInstaller.zipcompressed
MD5:0FEE915AC0B10F1A7169DF6972A76106
SHA256:FBAB30A9659FCA3366C94CEEEF5FBBC2EA9B3DC04E38A4B6ED235F148D93C163
7200Nero-Burning-ROM-2024-2.0.1.39.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\439F613B3D55693954E1B080DE3085B4_13A9E648A032C61467BDA0380F67EA43binary
MD5:F5D521375925BBACEDA048216DBA3ED5
SHA256:1101888053F689CB05164183037126ECCD4B6A79111C678972680232067CFAA1
7200Nero-Burning-ROM-2024-2.0.1.39.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94929790B3119AF4B3F5D66C747B122B_BD89444E43F6E3DA573BAF8E3E423D8Bbinary
MD5:62D1E090AA5CC89D1932B2D188DDDA30
SHA256:9598D4016FC0FCC3EDC03EC8FF43D245FD43601FA7C5564960E7039395B58AFB
7200Nero-Burning-ROM-2024-2.0.1.39.exeC:\Users\admin\AppData\Local\Temp\NeroInstaller\burningrom2024\temp\NeroInstaller\NeroInstaller.exeexecutable
MD5:08871AC383B2E17DC621212F868344AC
SHA256:6833BD88F4141AC69EAE4E94D3DE042B7D4E670DD8807EE9955A8AC3A004277F
7200Nero-Burning-ROM-2024-2.0.1.39.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94929790B3119AF4B3F5D66C747B122B_BD89444E43F6E3DA573BAF8E3E423D8Bbinary
MD5:FC61A9F244770590D4E4315CA4078D94
SHA256:0D21099CBA363B78F802CFC53B18D4EF5DF76B97AA9416ED02FC5F6C03348E9A
7720NeroInstaller.exeC:\Program Files (x86)\Nero\Nero Common\AdvrCntr6\NeroPatentActivation.exeexecutable
MD5:ACBC93DCAF4A1443A0B0533A3F026944
SHA256:D3681265C9759BB8B6564C5A695F7F1071633256AE65670F1C0445FAA27F52B7
7720NeroInstaller.exeC:\Program Files (x86)\Nero\Nero Common\AdvrCntr6\SpecialOffer.exeexecutable
MD5:41254DBA6E6920162F7EC1DB6775B109
SHA256:0AA6AA56E541D3E8EE9E809FFC62D40A8496E8DFF1679987E638F44C4375A4C0
7720NeroInstaller.exeC:\Program Files (x86)\Nero\Nero Common\AdvrCntr6\Eula_Nero_de-DE.rtftext
MD5:F1924C8009E3F2B7AA22E313625CDF59
SHA256:F605AC320C3F69E06868E532D83F652EBAE162535327570468B106743F7988F8
7720NeroInstaller.exeC:\Program Files (x86)\Nero\Nero Common\Nero KnowHow PLUS\neropack.binbinary
MD5:ACCD3F3ACC904ECF7FC8A6E097B23290
SHA256:22437C89A295106B3259082E1465E15B6DB6C759C20044946B93E5003D410F1B
7720NeroInstaller.exeC:\Users\admin\AppData\Local\Temp\NeroInstaller\burningrom2024\advrcntr6.zipcompressed
MD5:24EC6AE4342C1CFFACBA193B218F44B8
SHA256:561D672E263A26732DADF23F79C8F32A544E8286010BC371071A6BB9A4F2F1FC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7200
Nero-Burning-ROM-2024-2.0.1.39.exe
GET
200
151.101.66.133:80
http://ocsp2.globalsign.com/rootr6/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRi%2B7TJbHYn9EmJ9W03lecB7P%2BG7QQUrmwFo5MT4qLn4tcc1sfwf8hnU6ACEH8fLJAug9Djtvs77keLXoA%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7200
Nero-Burning-ROM-2024-2.0.1.39.exe
GET
200
151.101.194.133:80
http://ocsp.globalsign.com/gsgccr6alphasslca2023/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTYuQbxgZqJCf3D06HBxH57o5XEXgQUvQW384qTPHPLefoPhRKhd5YYkXQCDAOORurIgzWKgTZF1Q%3D%3D
unknown
whitelisted
7148
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
8184
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7200
Nero-Burning-ROM-2024-2.0.1.39.exe
193.24.237.217:443
login.nero.com
Die Netz-Werker Systemmanagement und Datennetze AG
DE
whitelisted
7200
Nero-Burning-ROM-2024-2.0.1.39.exe
193.24.239.229:443
www.nero.com
Die Netz-Werker Systemmanagement und Datennetze AG
DE
whitelisted
7200
Nero-Burning-ROM-2024-2.0.1.39.exe
205.234.175.175:443
dl9.nero.com
CACHENETWORKS
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.173
  • 23.48.23.147
  • 23.48.23.141
  • 23.48.23.156
  • 23.48.23.176
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.71
  • 40.126.31.3
  • 40.126.31.0
  • 20.190.159.129
  • 20.190.159.23
  • 20.190.159.0
  • 20.190.159.71
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
login.nero.com
  • 193.24.237.217
whitelisted
www.nero.com
  • 193.24.239.229
whitelisted
dl9.nero.com
  • 205.234.175.175
whitelisted
ocsp2.globalsign.com
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
  • 151.101.2.133
whitelisted
ocsp.globalsign.com
  • 151.101.194.133
  • 151.101.2.133
  • 151.101.130.133
  • 151.101.66.133
whitelisted

Threats

No threats detected
No debug info